Privacy Policy

Company:SAFIRA Clinical Research Ltd

Effective Date:5 November 2025

Last Reviewed:22 January 2026

Source:https://safiracr.com/privacy-policy/

1. Introduction

SAFIRA Clinical Research Ltd (“SAFIRA”, “we”, “us”, or “our”) is committed to protecting the privacy and personal data of all individuals with whom we interact, including clients, partners, contractors, employees, and clinical research stakeholders.

This Privacy Notice explains how we collect, use, store, share, and protect personal data in accordance with applicable data protection laws, including the EU General Data Protection Regulation (GDPR), the Data Protection Act 2018 (Ireland), and other relevant national and international regulations.

2. Who We Are (Data Controller)

SAFIRA Clinical Research Ltd
Barnagouloge, Cloughjordan
Co. Tipperary, E53 VW10
Ireland

Email: privacy@safira.partners

SAFIRA provides specialised clinical research and regulatory support services to the life sciences industry, including data-driven project management, user acceptance testing (UAT), and computerised system validation and software quality activities.

3. Categories of Personal Data We Process

Depending on the nature of our engagement, SAFIRA may process the following categories of personal data:

3.1 Client and Vendor Representatives

  • Names
  • Business contact details
  • Job title and organisation
  • Business correspondence

3.2 Employees and Contractors

  • Identification and contact details
  • Professional qualifications and experience
  • Training, competency, and performance records
  • Payroll, taxation, and HR-related information

3.3 Clinical Study Personnel (e.g. investigators, site staff)

  • Names and professional contact details
  • CVs, qualifications, and training documentation

3.4 Clinical Study Participants (where applicable)

  • Coded or pseudonymised data only
  • SAFIRA does not process directly identifiable participant data

3.5 Website Visitors

  • Limited technical data such as IP address, browser type, and device information
  • Cookies and similar technologies, as detailed in our Cookie Policy

4. How We Collect Personal Data

We collect personal data through:

  • Direct interactions with clients, vendors, employees, and contractors
  • Contractual documentation and business communications
  • Regulatory, compliance, and quality assurance activities
  • Technology platforms used for service delivery (e.g. validated systems and the GLOAT platform)
  • Publicly available sources, where lawful and relevant

5. Purposes and Legal Bases for Processing

SAFIRA processes personal data only where permitted under the GDPR, for the purposes and legal bases outlined below:

PurposeLegal Basis (GDPR)
Contract performance and service deliveryArticle 6(1)(b) – Contractual necessity
Compliance with legal and regulatory obligations (e.g. GCP, employment law, tax law)Article 6(1)(c) – Legal obligation
Quality assurance, audits, inspections, and risk managementArticle 6(1)(f) – Legitimate interests
Communication with clients, vendors, partners, and authoritiesArticle 6(1)(f) – Legitimate interests
Recruitment and human resource managementArticles 6(1)(b) and 6(1)(c)
Information security, system monitoring, and incident managementArticle 6(1)(f) – Legitimate interests
Marketing communications (where applicable)Article 6(1)(a) – Consent

Where processing is based on legitimate interests, SAFIRA ensures that such interests are not overridden by the rights and freedoms of the data subjects.

Special Category Data: Where SAFIRA processes special category personal data (e.g. health-related data in a clinical research context), such processing is carried out in accordance with Article 9(2)(i) or Article 9(2)(j) GDPR, based on public interest in public health or scientific research, and subject to appropriate safeguards.

6. Data Retention

Personal data are retained only for as long as necessary to fulfil the purposes for which they were collected and in accordance with applicable legal, contractual, and regulatory requirements.

Retention periods are defined in SAFIRA’s internal Data Retention and Disposal Framework, which ensures secure archiving, controlled access, and secure destruction of data when no longer required.

7. Data Protection and Security Measures

SAFIRA operates a comprehensive Quality Management System (QMS) that includes documented procedures covering data protection, information security, access control, incident response, business continuity, and data retention.

Our framework aligns with:

  • ISO 9001 quality management principles
  • ISO/IEC 27001 information security standards
  • ICH-GCP E6 (R3)
  • GDPR data integrity and accountability principles

Technical and organisational measures include:

  • Role-based access control and least-privilege principles
  • Encrypted data storage and data transmission
  • Secure backups and disaster recovery arrangements
  • Regular staff training on data protection and cybersecurity
  • Vendor qualification, risk assessment, and ongoing monitoring

8. Data Sharing and International Transfers

SAFIRA does not sell personal data.

We may share personal data with:

  • Authorised employees and contractors subject to confidentiality obligations
  • Regulatory and supervisory authorities where legally required
  • Approved third-party service providers supporting our operations (e.g. hosting, auditing, training, or IT services)

Where personal data are transferred outside the European Economic Area (EEA), such transfers are safeguarded by appropriate mechanisms, including EU Standard Contractual Clauses (SCCs) or equivalent legally recognised transfer safeguards.

9. Data Subject Rights

Individuals whose personal data are processed by SAFIRA have the following rights under the GDPR:

  • Right of access
  • Right to rectification
  • Right to erasure (“right to be forgotten”)
  • Right to restriction of processing
  • Right to data portability
  • Right to object to processing
  • Right to withdraw consent at any time, where processing is based on consent
  • Right to lodge a complaint with a supervisory authority

Requests to exercise these rights may be submitted to: privacy@safira.partners

The competent supervisory authority in Ireland is the Data Protection Commission (DPC).

10. Personal Data Breach Notification

In the event of a personal data breach, SAFIRA will assess the risk and, where required, notify:

  • The relevant Data Protection Authority, and
  • Affected individuals or customers,

in accordance with GDPR Articles 33 and 34.

11. Updates to This Privacy Notice

This Privacy Notice may be updated periodically to reflect regulatory developments or changes in SAFIRA's processing activities. The most current version will always be available on our website:

https://safiracr.com/privacy-policy/

12. Contact Details

For any questions regarding this Privacy Notice or SAFIRA's data protection practices, please contact:

Data Protection Officer (DPO)
Francis Gon
Email: dpo@safira.partners
Address: Barnagouloge, Cloughjordan, Co. Tipperary, Ireland